Decode and fix a failing SonarCloud or CodeQL quality gate on a PR. Pulls the actual issues via API, separates real defects from metric artifacts, fixes the cheap and legitimate ones, and reports remaining items as an explicit judgment call. Use when a Sonar/CodeQL gate is red.
Instalação
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Decode and fix a failing SonarCloud or CodeQL quality gate on a PR. Pulls the actual issues via API, separates real defects from metric artifacts, fixes the cheap and legitimate ones, and reports remaining items as an explicit judgment call. Use when a Sonar/CodeQL gate is red.
gate
A failing quality gate usually mixes real issues with metric artifacts. Decode it
before touching code, and never game a metric silently.
Workflow
When the user invokes /gate [optional: PR number]:
Get the gate status and per-condition breakdown:
curl -s "https://sonarcloud.io/api/qualitygates/project_status?projectKey={KEY}&pullRequest={N}"
Pull the ACTUAL issues, don't reason from ratings alone:
Smells: same issues endpoint with types=CODE_SMELL
Triage each into: real defect / metric artifact / false positive. Common artifacts:
Coverage 0%: no report uploaded, or the code is genuinely untestable
(UI/frontend/JS). Fix by generating real coverage for testable code AND
excluding untestable code via sonar.coverage.exclusions.
Duplication: often shared boilerplate — extract it.
JS "expected assignment/expression": a template placeholder Sonar parses
as raw JS. Make placeholders comments.
"prefer top-level await": false positive when code runs in an injected
async wrapper (e.g. streamlit-js).
Fix the cheap, legitimate ones. For coverage gaps in DB/integration code, add
integration tests with real service containers rather than excluding.
Push, wait for the rescan (gh run watch), re-query the gate to CONFIRM green.
Report any remaining red condition as an explicit judgment call to the user —
don't over-exclude to force a pass.
Important
Distinguish "real security/correctness problem" from "metric hygiene"; report
the distinction honestly and fix what's genuinely worth fixing.
Never game a metric (e.g. over-broad coverage exclusions) just to force a
green gate — report a remaining red condition as an explicit judgment call.
gh auth: prefix gh with unset GITHUB_TOKEN && (an invalid token may
shadow the login). SonarCloud's read API needs no token for public projects.